{"id":"CVE-2019-16751","aliases":["GHSA-mvqr-r76c-wm5f"],"url":"https://o3.security/vulnerability/CVE-2019-16751","summary":"Devise Token Auth vulnerable to Cross-site Scripting","details":"An issue was discovered in Devise Token Auth through 1.1.2. The omniauth failure endpoint is vulnerable to Reflected Cross Site Scripting (XSS) through the message parameter. Unauthenticated attackers can craft a URL that executes a malicious JavaScript payload in the victim's browser. This affects the fallback_render method in the omniauth callbacks controller.","published":"2019-09-24T18:15:11.030Z","modified":"2026-07-08T11:47:41.867853Z","cvss":{"score":6.1,"severity":"MEDIUM","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N"},"epss":null,"cisaKev":null,"exploitsKnown":1,"affectedPackages":[{"ecosystem":"RubyGems","name":"devise_token_auth","fixedVersion":"1.1.3"}],"fix":null,"references":[{"type":"EVIDENCE","url":"https://github.com/lynndylanhurley/devise_token_auth/issues/1332"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-07-08T11:47:41.867853Z"}}